DEVRAJ SARKAR · INDEPENDENT AI & CYBERSECURITY ADVISOR

AI Strategy, Governance & Cybersecurity for the Agentic Enterprise.

Advising C-suite and board leaders on the transition from AI experimentation to secure, governed and responsible autonomy.

Based in Kolkata, India, I advise organizations on building AI as a secure, governed and business-driven enterprise capability—bringing together AI strategy, Agentic AI, Responsible AI, AI governance, AI security, cyber risk and assurance.

23+Years in IT
15+Years Consulting
ISO/IEC 42001 & 27001Lead Auditor
C-Suite & BoardAdvisory
STRATEGY AI GOVERNANCE SECURITY TRUST

THE NEXT ENTERPRISE TRANSITION

AI is moving from answering questions to taking action.

Agentic AI systems can reason, plan, use tools, access enterprise data, collaborate with other agents and execute multi-step business processes. That changes the enterprise risk equation.

Understand the autonomy challenge →
01ExperimentExplore possibilities
02AdoptScale use cases
03GovernEstablish controls
04DelegateEnable agents
05AutonomyOperate responsibly

ADVISORY FOCUS

Where AI, security, governance and business value converge.

Focused advisory and assurance for C-suite and board leaders moving from experimentation to enterprise-scale AI, in India and internationally.

01

AI Strategy & Transformation

Connect AI investment with business priorities, operating-model transformation, governance and measurable value.

Explore advisory →
02

Agentic AI Security

Design trusted autonomous systems with bounded authority, identity, tool controls and oversight.

Explore Agentic AI →
03

Responsible AI & Governance

Build policy, accountability, risk classification, lifecycle controls and evidence.

Explore governance →
04

AI Assurance

Assess whether governance structures and controls operate as intended and can be demonstrated with evidence.

Explore assurance →
05

Cybersecurity & Digital Risk

Strengthen identity, cloud, secure engineering, Zero Trust, DevSecOps and digital risk governance.

Explore cybersecurity →
06

ISO/IEC 42001 & AI Management Systems

Connect governance obligations, risk treatment, documented evidence, audit and continual improvement.

Explore ISO/IEC 42001 →

FEATURED FOCUS · AGENTIC AI

The question is no longer just what AI can do. It is what AI should be allowed to do.

AI agents may determine how to achieve an objective, select tools, retrieve information, invoke APIs, collaborate with other agents and act on behalf of users or organizations.

What is AI Agent Security?

AI Agent Security is the discipline of protecting autonomous or semi-autonomous AI systems from excessive permissions, manipulated instructions, unsafe tool use, identity abuse, data leakage and unaccountable actions.

Explore Agentic AI security →
AGENT AUTONOMY
IdentityWho is the agent?
AuthorizationWhat can it do?
MemoryWhat does it retain?
ToolsWhat can it invoke?
OversightWhen must humans approve?
AuditabilityCan actions be reconstructed?

RESPONSIBLE AUTONOMY MODEL

Autonomy is a spectrum. Governance should scale with it.

LEVEL 1

Assist

AI recommends. Human decides and acts.

LEVEL 2

Collaborate

AI performs defined tasks. Human supervises.

LEVEL 3

Delegate

AI executes approved processes within boundaries.

LEVEL 4

Autonomous

AI plans and executes with exception-based oversight.

LEVEL 5

Multi-Agent

Multiple agents coordinate decisions and actions.

THE AUDITOR'S PERSPECTIVE

Trust requires evidence.

AI governance cannot stop at policies and principles. Organizations need evidence that controls operate in practice.

CONTROL QUESTION

Can an AI agent perform a high-impact action without independent authorization?

RISK

A manipulated or incorrectly configured agent could act beyond its intended authority.

EVIDENCE

Agent identities, IAM roles, API scopes, tool permissions, execution logs and approvals.

CONTROL EXPECTATION

Explicitly scoped privileges and stronger approval for consequential actions.

RESEARCH

Analysis for people responsible for technology risk.

Explore all research →
AGENTIC AI

AI Agent Security

Identity, permissions, memory, tools, delegation and accountability in autonomous AI systems.

Research library →
AI GOVERNANCE

ISO/IEC 42001

Moving from Responsible AI principles to a structured AI management system.

Research library →
AI SECURITY

AI Application Assurance

A practical lens across models, data, RAG, identity, applications and runtime controls.

Research library →
CYBERSECURITY

Zero Trust for Agentic AI

How machine identities and delegated authority change the traditional Zero Trust model.

Research library →

EXPERIENCE BEHIND THE ADVISORY

Devraj Sarkar

Independent AI & Cybersecurity Advisor · C-Suite & Board Advisory

I bring 23+ years of overall IT experience, including 15+ years in consulting, spanning AI strategy, cybersecurity, cloud, DevSecOps, AIOps, governance, risk and enterprise transformation.

I hold an MBA (IT) and ISO/IEC 42001 & ISO/IEC 27001 Lead Auditor credentials. My advisory focus sits at the intersection of enterprise AI, governance, cybersecurity and assurance.

INDEPENDENT AI & CYBERSECURITY ADVISORY

Executive judgment for AI, governance and cyber risk.

Devraj Sarkar is an independent AI and cybersecurity advisor based in Kolkata, India. He advises C-suite and board leaders on AI strategy, Agentic AI, AI governance, AI security, cyber risk and assurance, supporting organizations in India and internationally.

About Devraj Sarkar →
01StrategyBusiness-aligned AI
02GovernanceAccountability & controls
03SecurityAI & cyber risk
04AssuranceEvidence & audit
05LeadershipC-suite & board

INDEPENDENT ADVISORY

Complex technology. Clearer risk decisions.

For AI strategy, governance, Agentic AI, security, assurance or cyber-risk requirements in India or internationally, describe the decision you are facing and the context around it.

Discuss an Advisory Requirement ↗